Trust
Security and Trust
Cyber Health Score is designed around multi-tenancy, organisation isolation, role-based access, audited support access, fail-closed commercial and assessment controls, and durable processing separated from ephemeral coordination. This page summarises public-safe principles. It is not an auditor-ready attestation and does not claim ISO, SOC 2, Cyber Essentials, or penetration-test certification.
Product boundaries
What CHS does, and what it does not do
Bounded external posture platform
Cyber Health Score supports External Attack Surface Management, Continuous Assessment, Exposure Priority, Change Intelligence, Brand Protection, Evidence Vault, Supplier Assurance and Authorised Validation within declared product boundaries.
Not penetration testing
Cyber Health Score is not a red-team platform, exploit framework, authenticated internal vulnerability scanner, or guarantee that every vulnerability will be found.
Not internet-wide scanning
Passive Monitoring starts from verified customer seeds and applies traversal bounds. It does not perform internet-wide scanning or unrestricted enumeration.
Not automatic active authority
Discovered hosts, CDN edges, SaaS providers and related observations do not silently inherit Continuous Assessment or Authorised Validation authority.
Not certification
Reports and Evidence Vault support audit preparation. They do not constitute ISO, SOC 2, Cyber Essentials, PCI DSS or penetration-test certification unless separately achieved and contracted.
Security principles
How trust is built into the product
Authentication and authorisation
Authentication uses secure session cookies configured for the hosted environment. Authorisation is membership and role based. Workspace administrators control who can invite users, configure assessment policy, and grant time-limited support access.
Multi-tenancy and organisation isolation
Tenant data is scoped server-side to the organisation. Customer inventory, findings, alerts, remediation, reports, and CHS Agent answers are organisation-bounded. Cross-tenant access is not part of the product model.
Passive Monitoring versus Continuous Assessment
Passive Monitoring and Attack Surface inventory intelligence do not silently grant Continuous Assessment authority. Continuous Assessment requires explicit customer consent and remains bounded. Discovered third-party, CDN, SaaS, hosting, and ASN observations are informational and do not inherit customer assessment consent. Observed external exposure chains describe evidence-backed relationship topology only and are not internal attack paths.
Outbound request protections
Authorised external assessment paths retain public-IP validation, redirect revalidation, and DNS-rebinding mitigations. Durable workers load persisted jobs and revalidate consent and authority at execution time.
Auditability and Evidence Vault
Material tenant and operator actions are designed to be auditable. Governance, Evidence Vault, and reporting support stakeholder-ready evidence without promising certification outcomes.
Data handling
Privacy and data handling
Cyber Health Score processes account, organisation, Attack Surface inventory, assessment, finding, remediation, reporting and support data needed to operate the service for your tenant.
Tenant data is organisation-scoped. Cross-tenant access is not part of the product model.
Support access is tenant-consented, scoped, time-bound, revocable and audited when used.
This overview is not a complete privacy notice or Data Processing Agreement. Contractual data-processing terms are provided separately for commercial customers.
Retention
Retention follows plan entitlements and contractual configuration where supported. Export-before-delete and approval-gated deletion pathways exist for responsible lifecycle management. Destructive deletion remains disabled by default.
Subprocessor transparency
Hosted deployments commonly rely on infrastructure and delivery providers for application hosting, database, email delivery, payments and durable job delivery. Exact subprocessors for a commercial engagement are confirmed in that engagement's documentation and may change with notice under contract.
Vulnerability disclosure
We welcome responsible reports of security issues in the Cyber Health Score application and related public services.
- Provide enough detail to reproduce the issue, including affected URLs, approximate time and impact.
- Do not access customer tenant data beyond what is required to demonstrate the issue.
- Do not perform destructive testing, denial-of-service, social engineering of staff, or mass automated scanning against production.
- Allow a reasonable remediation window before public disclosure.
Security and architecture FAQs
Does Cyber Health Score certify compliance?
No. Evidence Vault, reports and governance readiness support preparation and stakeholder communication. Certification claims require separate achievement and contractual confirmation.
How is tenant isolation enforced?
Server-side authorisation scopes customer inventory, findings, alerts, remediation, reports and CHS Agent answers to the organisation. Cross-tenant access is not part of the product model.
What is the difference between Passive Monitoring and Continuous Assessment?
Passive Monitoring expands Attack Surface visibility from approved passive sources after verification. Continuous Assessment performs bounded external posture checks only against authorised assets.
Does Supplier Assurance allow supplier scanning?
No. A commercial supplier relationship recorded in Supplier Assurance does not authorise Cyber Health Score to actively assess that supplier.
What is Authorised Validation?
Authorised Validation is an explicit, time-bound, target-specific and technique-specific authority control plane. Existing assessment consent never grants it. Live adversarial validation remains disabled unless separately authorised.
Where do I report a security issue or abuse?
Use the vulnerability disclosure guidance on the Security pages, or contact us with a security intent. For suspected abuse of the platform, use the abuse reporting page.
Questions? Contact us or read the Trust centre.
Trust centre